TakePAways6
• Many recent catastrophic failures are
secure coding errors, not crypto errors
• Static analyzers are not enough
• Manual inspection is not enough
• Source code can result in unexpected
binary code
• Subject matter experts (protocols, crypto,
network) may bring more perspective than
“enough” eyes